Trust and Turbulence

Josh Brickman

Joshua Brickman spent more than 20 years working in cybersecurity certifications, government assurance, and global security regulation. This podcast explores the intersection of security, AI, regulation, and trust — from Common Criteria and FIPS 140 to post-quantum cryptography, supply chain security, cloud assurance, and the EU Cyber Resilience Act. The show turns complex technical and policy issues into practical conversations for businesses, policymakers, technologists, and consumers.

Episodes

  1. 1 day ago

    From Q-Day to SolarWinds: Can Security Certification Keep Up?

    Cybersecurity threats are evolving faster than the certification programs designed to provide assurance. So can programs like Common Criteria and FIPS keep pace?In this episode of Trust and Turbulence, I’m joined by Alicia Squires, Industry Principal for FIPS at AWS, and Kevin Micciche, Chief Technologist at HPE, two long-time practitioners in security certification and cryptography. We start with SolarWinds and a deceptively simple question: could a security evaluation have caught it? From there, the conversation moves to the tension between rigorous assurance and getting products to market, and why developing the next generation of security evaluators matters.Then we turn to Q-Day and post-quantum cryptography: crypto inventories, cryptographic agility, migration challenges, and what vendors and governments should be doing now. We also explore an increasingly important wildcard: AI. Could AI change the cryptographic threat? Can it find vulnerabilities that previously weren't practical to exploit? And can the same technology be used to make security certification faster without sacrificing trust?Finally, we look ahead at a world where security requirements are multiplying rather than converging—and ask whether AI, automation, and better reuse of security evidence can help certification keep up.Disclaimer: Views expressed are the guests' own and do not represent their employers.About the GuestsKevin Micciche is Chief Technologist for HPE Networking Platform Trust, where he leads work in cryptography, platform security, and the transition to post-quantum cryptography. A longtime security certification practitioner, Kevin has certified more than 150 products spanning 16 years against Common Criteria and FIPS requirements. https://www.linkedin.com/in/micciche/Alicia Squires is the FIPS Security Industry Principal on AWS's Cryptography team, with more than 25 years of experience in security certification, cryptography, and international compliance. Previously, she spent 15 years at Cisco, including leading its Global Certifications Team. Alicia is also a founding member of the Common Criteria Users Forum and served as its Chair for seven years. https://www.linkedin.com/in/alicia-squires/Title Chapters and Timestamps00:00 Kevin Micciche and Alicia Squires00:53 Can Security Certification Prevent the Next SolarWinds?13:52 Who Will Be the Next Generation of Security Evaluators?19:51 PQC, Q-Day and the AI Wild Card33:49 Can AI Fix Security Certification?40:17 The Future of Security CertificationMentioned in this EpisodeAWS CMVP queue-time dashboards, posted via the Cryptographic Module User Forum — https://cmuf-workspace.org/Products/Projects/Messages.aspx?prjID=17&id=622#ICT Compliance Podcast with Matt Campagna on post-quantum cryptography — https://youtu.be/oaZmlzcHrmc?si=709A7zkiLIfF2XHnICT Compliance Podcast with Dr. Lily Chen (NIST) — https://youtu.be/oaZmlzcHrmc?si=709A7zkiLIfF2XHnFilippo Valsorda on AES-128 and Grover's algorithm — https://words.filippo.io/128-bits/NIST CSWP 39, on cryptographic agility — https://csrc.nist.gov/pubs/cswp/39/considerations-for-achieving-cryptographic-agility/ipdExecutive Order 14028 (software supply chain and SBOMs) and Executive Order 14412, Section 6(b) (CMVP acceleration)-- https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurityOMB M-21-07, the phased IPv6 mandate Kevin offers as a model for PQC migration– https://www.gsa.gov/directives-library/internet-protocol-version-6-ipv6-policy-1Cryptographic Module User Forum (CMUF) — free to join — https://www.cmuf.org/Music by Mikhail Smusev from PixabayAnimation and Logo by Edith Brickman

  2. 13 Aug

    Can We Automate Trust? The Future of FIPS 140 and Common Criteria

    Can we automate trust? And if we can, what happens to cybersecurity certification as we know it?In this episode of Trust & Turbulence, I’m joined by longtime colleagues Ashit Vora and Shawn Geddis, who are both building technologies designed to rethink how security certification gets done — but they’re approaching the problem in very different ways.Ashit is using AI to automate Common Criteria certification, with an eye toward expanding into areas such as the EU Cyber Resilience Act. Shawn is taking an intelligent automation (IA) approach to FIPS 140 and other assurance processes, emphasizing deterministic testing, standardized data, and machine-to-machine evidence exchange.We dig into some big questions:• What’s actually broken in today’s FIPS 140 and Common Criteria processes? • What’s the difference between AI and intelligent automation — and where does each belong? • Can automated testing and evidence ever earn the same trust as traditional human-driven evaluation? • What happens to certification labs as more of the work becomes automated? • Could continuous certification replace today’s point-in-time model? • Will the EU Cyber Resilience Act (CRA) accelerate automation simply because traditional compliance cannot scale? • How should Common Criteria and the broader standards community deal with AI? • And what happens when increasingly fragmented global requirements undermine the old goal of “evaluate once, sell everywhere”? This is also a conversation among three people who have worked together in the FIPS and Common Criteria community for well over a decade, so we get into some history, war stories, disagreements, and more than a few analogies — including teddy bears, taxes, Britney Spears and building a house.Can we really automate trust? Or does human judgment always have to remain at the center of cybersecurity assurance?That’s what we explore in this episode.If you enjoy Trust & Turbulence, please like, subscribe, and share your thoughts in the comments — particularly where you think AI and automation belong in the future of cybersecurity certification.About the GuestsShawn GeddisShawn Geddis spent more than 25 years at Apple, where he built the first Apple Platform Security Certifications Program and led engineering work for global platform certifications. He also built Apple’s SECLAB, its NVLAP-accredited first-party cryptographic laboratory, serving as lab manager, tooling developer, and—in his words—“evidence whisperer.” Shawn has since founded Katalyst LLC, focused on developing approachable automation and tooling for security certification.Ashit VoraAshit Vora is Co-Founder of Autonomi, an AI-enabled automation platform focused on transforming standards-based product security certification. Previously, Ashit co-founded Acumen Security, which grew into a leading product security certification provider before being acquired by Intertek. Earlier, he led Cisco’s U.S. government certification business supporting programs enabling approximately $1.5 billion in annual revenue. His work spans more than two decades of product security, certification, testing, standards, and commercialization. Music by Mikhail Smusev from PixabayLogo

  3. 3 Jul

    The Perpetual Student with Jim West

    In this episode of Trust and Turbulence, I sit down with cybersecurity leader, author, podcaster, and lifelong learner Jim West. From his early days repairing computers at CompUSA to advising senior government leaders on cybersecurity, quantum computing, and national security, Jim's career has been anything but ordinary.We discuss cybersecurity, AI, quantum computing, the future of digital trust, life in the Middle East, career development, and why Jim proudly calls himself a "perpetual student."Whether you're a cybersecurity professional, technology enthusiast, or simply curious about how today's leaders navigate a rapidly changing world, this conversation offers valuable insights and plenty of memorable stories.Topics Discussed• Lifelong learning and professional growth• Cybersecurity leadership and national security• Commercial Solutions for Classified (CSfC)• Quantum computing and post-quantum cryptography• Artificial intelligence and deepfakes• International travel and cultural perspectives• Movies, creativity, and thinking differentlyGuest: Jim West, Author, Podcaster, Cybersecurity ExpertHosted by: Joshua Brickman 00:17 Meet Jim West02:14 The Perpetual Student Mindset13:25 Jim's Origin Story in IT & Cyber14:26 Iraq & Working Near the President17:18 25+ Years Living Overseas19:49 CSfC & Common Criteria Deep Dive38:32 Cybersecurity for Everyday Life46:00 The Quantum Threat & Post-Quantum Crypto56:27 Movie Review Wrongs01:05:32 Where to Find Jim WestMusic by Mikhail Smusev from PixabaySocials:LinkedIn: https://www.linkedin.com/in/jimwest1/https://jimwestauthor.com/https://topcyberpro.com/

About

Joshua Brickman spent more than 20 years working in cybersecurity certifications, government assurance, and global security regulation. This podcast explores the intersection of security, AI, regulation, and trust — from Common Criteria and FIPS 140 to post-quantum cryptography, supply chain security, cloud assurance, and the EU Cyber Resilience Act. The show turns complex technical and policy issues into practical conversations for businesses, policymakers, technologists, and consumers.